Description
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32816 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Wed, 26 Feb 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpmet
Wpmet metform Elementor Contact Form Builder |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wpmet:metform_elementor_contact_form_builder:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpmet
Wpmet metform Elementor Contact Form Builder |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:28.656Z
Reserved: 2024-04-26T18:15:23.917Z
Link: CVE-2024-4266
Updated: 2024-08-01T20:33:53.023Z
Status : Modified
Published: 2024-06-11T08:15:50.850
Modified: 2026-04-08T18:21:43.677
Link: CVE-2024-4266
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD